Privacy Policy

Your data, handled honestly.

How CredaFi collects, uses, stores, shares and protects your personal data when you use our chat-native AI payment assistant — written to comply with the Nigeria Data Protection Act 2023 and CBN requirements.

Effective 14 July 2025 · Version 1.0 · Nigeria Data Protection Act 2023 · NDPR 2019

01Who we are

CredaFi Limited ("CredaFi", "we", "us" or "our") is a financial technology company incorporated under the laws of the Federal Republic of Nigeria, with its office at 2 Idimu Egbeda Road, Egbeda, Lagos State, Nigeria. We operate a WhatsApp-native AI assistant through which users can send and receive payments, buy airtime and data, pay bills, get spending insights and resolve transfer issues by chatting, sending an image or sending a voice note.

CredaFi is the data controller for the personal data described in this Policy. Our Chief Executive Officer is Mr Chris Bekee and our Chief Operating Officer is Mr Judgewill Churchill. A Data Protection Officer is appointed and contactable below.

02Scope

This Policy does not apply to third-party websites, banking partners or services linked from CredaFi. Please read their own privacy notices independently.

  • All users who interact with CredaFi via WhatsApp, including senders and recipients of payments and airtime/bill payment users.
  • All visitors to our website, social media pages and other digital touchpoints operated by CredaFi.
  • All individuals whose personal data we process while providing financial services, including KYC verification.

03Personal data we collect

  • Identity and contact data: full legal name, WhatsApp phone number, date of birth, gender, residential address and email address where provided.
  • Government identity data (KYC): Bank Verification Number (BVN), National Identification Number (NIN), national ID, voter's card or international passport details, passport photograph and facial biometric data where liveness verification is used.
  • Financial and transaction data: bank account numbers and bank names, transaction history, wallet balance, receipts, airtime and bill payment records, and your payment PIN stored only in hashed form — never in plaintext.
  • Device and technical data: phone number and device identifier, IP address and approximate location, device type and operating system, message timestamps and interaction logs.
  • Behavioural and usage data: transaction frequency, patterns and velocity, beneficiary lists and engagement patterns.
  • Communications data: WhatsApp message content relating to financial instructions, voice-note transcriptions where voice commands are used, support correspondence, feedback and complaints.

04How we collect your data

  • Directly from you when you register, transact or contact support.
  • Through KYC verification using BVN and NIN lookups via authorised identity verification providers.
  • Automatically through your use of our WhatsApp assistant, including transaction logs and interaction metadata.
  • From our banking partners and payment infrastructure when transactions are executed.
  • From publicly available sources for fraud prevention and AML compliance.

05Legal basis for processing (NDPA 2023)

Legal basisProcessing activity
ConsentMarketing communications and optional data sharing with third-party partners.
Contract performanceProcessing payments and executing transactions on your behalf.
Legal obligationKYC/AML compliance, CBN and NFIU regulatory reporting, tax obligations and fraud prevention.
Legitimate interestFraud detection, product improvement and security monitoring.
Vital interestEmergency fraud prevention where immediate action is required to protect funds.

06How we use your data

  • Service delivery: processing payment instructions, executing transfers, facilitating airtime and bill payments, maintaining your wallet and history, and sending confirmations and receipts.
  • KYC and regulatory compliance: verifying identity through BVN and NIN as required by the CBN, meeting AML and counter-terrorism-financing obligations, reporting to the CBN, NFIU and other authorities, and retaining records for statutory periods.
  • Risk and fraud assessment: monitoring transaction behaviour and detecting anomalous or suspicious patterns.
  • Fraud prevention and security: monitoring for suspicious patterns, verifying authenticity through PIN and device checks, blocking high-risk transactions and investigating incidents.
  • Product improvement: analysing aggregated and anonymised usage data, improving models on anonymised data, and conducting user research.
  • Communications and support: answering queries and complaints, sending service, security and account notifications, and sending marketing only where you have consented.

07Data sharing and disclosure

We do not sell your personal data. We share it only as follows:

  • Banking and payment partners: necessary transaction data is shared with licensed banking partners and payment processors to execute your instructions, under confidentiality and data processing agreements.
  • Identity verification providers: BVN and NIN are shared with authorised verification providers to complete KYC, on a secure need-to-know basis, as mandated by CBN regulations.
  • Regulators and law enforcement: we share data with the CBN, NFIU, EFCC and other competent authorities where required by law, court order or regulatory directive.
  • Technology service providers: cloud infrastructure, WhatsApp Business API providers and analytics platforms, strictly for service delivery and bound by data processing agreements.
  • Business transfers: in a merger, acquisition or sale, data may transfer to the acquiring entity subject to the same protection, and you will be notified.

08Data retention

Data categoryRetention period
KYC and identity data7 years from account closure (CBN AML requirement)
Transaction records7 years from transaction date (CBN requirement)
Customer support records3 years from last interaction
Marketing consent recordsUntil consent is withdrawn, plus 1 year
Fraud investigation dataAs required by law enforcement or the courts
Anonymised analytics dataIndefinitely (non-personal, aggregated)
Inactive account data2 years from last transaction, then anonymised

09Your data rights

Under the Nigeria Data Protection Act 2023 you have the right to:

  • Access: request a copy of the personal data we hold about you; we respond within 30 days.
  • Rectification: request correction of inaccurate or incomplete data.
  • Erasure: request deletion, subject to records we are legally required to keep (KYC, transactions).
  • Object: object to direct marketing at any time, and to processing based on legitimate interests where it affects your fundamental rights.
  • Portability: receive your data in a structured, commonly used, machine-readable format.
  • Withdraw consent: withdraw consent at any time, without affecting the lawfulness of prior processing.
  • Complain: lodge a complaint with the Nigeria Data Protection Commission (NDPC) at www.ndpc.gov.ng.

10How to exercise your rights

Contact us through WhatsApp (+234 816 994 5302), the Help & Support line (+234 816 994 5302) or privacy@usecredafi.com.ng. We acknowledge requests within 72 hours and respond fully within 30 days. We may ask you to verify your identity before acting on a request.

11Data security

  • Encryption of data in transit using TLS 1.2 or higher, and AES-256 encryption at rest.
  • Payment PINs stored using one-way cryptographic hashing (bcrypt or Argon2) — never in readable form.
  • Multi-factor authentication for all staff accessing production systems, with least-privilege, need-to-know access controls and audit logging.
  • Regular penetration testing and independent security audits, real-time fraud and transaction monitoring, and secure API gateways with rate limiting and IP allow-listing.
  • Mandatory data protection training for employees and contractors, data processing agreements with all vendors, and a documented incident response plan.
  • Where a breach is likely to risk your rights and freedoms, we notify the NDPC within 72 hours and affected users without undue delay.

12Cookies and tracking

Our WhatsApp service does not use browser cookies. Our website uses strictly necessary cookies, and — only with your consent — preference, analytics and marketing cookies. Full detail, retention periods and how to withdraw consent are set out in our Cookies Policy.

13Children's privacy

Our services are not directed at persons under 18, and we do not knowingly collect their data. Age is verified during KYC. If you believe a minor has provided us with personal data, contact us and we will delete it promptly; accounts found to belong to minors are suspended immediately.

14International data transfers

Our primary data infrastructure is in Nigeria. Some technology providers, including cloud infrastructure and WhatsApp Business API providers, may process data abroad, and completing a cross-border payment necessarily involves transferring limited data to the destination country.

  • We transfer data outside Nigeria only where the receiving country offers adequate protection as determined by the NDPC, or appropriate safeguards such as NDPC-recognised standard contractual clauses are in place.
  • Where a transfer is necessary to perform your instruction — for example a cross-border payment — we transfer the minimum data required to complete and settle it.
  • We do not transfer your data to countries without adequate protection absent your explicit consent or another lawful ground.

15Automated decision-making

CredaFi uses automated processing, including machine-learning models, to detect fraud risk and generate spending insights. This means certain checks may occur without human intervention.

The factors considered include transaction frequency, average transaction volume, account age and spending pattern consistency. No protected characteristics — race, religion, gender or ethnicity — are used.

  • You may request human review of any automated decision that significantly affects you, within 14 days of the decision.
  • You may ask us to explain the logic behind the decision in plain language.
  • You may contest a decision and submit additional information for reconsideration.

16WhatsApp data processing

Our service is delivered through WhatsApp, operated by Meta Platforms Ireland Ltd. Using CredaFi on WhatsApp also subjects you to Meta's Privacy Policy and WhatsApp's Terms of Service.

  • We access WhatsApp only through the official WhatsApp Business Platform, and cannot see your personal WhatsApp messages outside your conversation with CredaFi.
  • WhatsApp applies its own encryption; we receive and process the content of the messages you send to CredaFi in order to execute your instructions.
  • We do not access your WhatsApp contacts, profile picture or status updates.

17Changes to this Policy

  • We notify you by WhatsApp message at least 14 days before material changes take effect.
  • The updated Policy is posted on our website with a new effective date.
  • Where the law requires it, we will seek fresh consent for new processing activities.

18Contact us

  • Data Protection Officer — CredaFi Privacy Team: privacy@usecredafi.com.ng
  • WhatsApp: +234 816 994 5302 · Help & Support: +234 816 994 5302
  • Postal address: 2 Idimu Egbeda Road, Egbeda, Lagos State, Nigeria
  • Response time: 72 hours for acknowledgement, 30 days for a full response.
  • Unsatisfied? Escalate to the Nigeria Data Protection Commission (NDPC) at www.ndpc.gov.ng.

19User acknowledgement

  • You have read and understood this Privacy Policy.
  • You are at least 18 years of age.
  • You consent to the collection, use and processing of your personal data as described here.
  • You understand your rights and how to exercise them. During onboarding you will be asked to confirm acceptance explicitly in the chat.

Prepared in compliance with the Nigeria Data Protection Act 2023, the Nigeria Data Protection Regulation 2019, the CBN Consumer Protection Regulations 2019, the CBN AML/CFT Regulations 2022, the Money Laundering (Prevention and Prohibition) Act 2022, the Cybercrimes (Prohibition, Prevention, Etc.) Act 2015 and the Companies and Allied Matters Act 2020.